Commit Graph

3 Commits

Author SHA1 Message Date
Austin McKinley bf71c329c6 build: bump Node to 24.18 for June 2026 security releases
The June 18 2026 Node.js security releases fix several HIGH/MEDIUM CVEs
on the 24.x line, with 24.17.0 as the first patched release. The service
images were pinned to 24.15, below that line. Bump to 24.18-alpine3.23
(latest 24.x) to pick up the fixes, including:

- CVE-2026-48618 (HIGH) TLS wildcard-depth auth bypass
- CVE-2026-48933 (HIGH) WebCrypto AES integer overflow crash
- CVE-2026-48928/48930/48934 (MEDIUM) TLS/SNI identity verification bypasses
- CVE-2026-48619 (MEDIUM) unbounded HTTP/2 memory growth via ORIGIN frames

Advisory: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-05 21:20:04 -07:00
DS Boyce 6f4ae14f36 Update to Node.js v24 (#10419) 2026-05-05 11:51:42 -07:00
devin ivy 55812b0394 Bsky short link service (#4542)
* bskylink: scaffold service w/ initial config and schema

* bskylink: implement link creation and redirects

* bskylink: tidy

* bskylink: tests

* bskylink: tidy, add error handler

* bskylink: add dockerfile

* bskylink: add build

* bskylink: fix some express plumbing

* bskyweb: proxy fallthrough routes to link service redirects

* bskyweb: build w/ link proxy

* Add AASA to bskylink (#4588)

---------

Co-authored-by: Hailey <me@haileyok.com>
2024-06-21 12:41:06 -04:00